EPCS Third party audits the CPA perspective. 13 September 2012



Similar documents
Service Organization Controls. Managing Risks by Obtaining a Service Auditor s Report

Cybersecurity and the AICPA Cybersecurity Attestation Project

CSA Position Paper on AICPA Service Organization Control Reports

Service Organization Controls. Managing Risks by Obtaining a Service Auditor s Report

SECURITY AND EXTERNAL SERVICE PROVIDERS

Re: Docket No. DEA-218, Electronic Prescriptions for Controlled Substances, Interim Final Rule with Request for Comment

Baker Tilly refers to Baker Tilly Virchow Krause, LLP, an independently owned and managed member of Baker Tilly International. Understanding SOC 3

SAS No. 70, Service Organizations

Goodbye, SAS 70! Hello, SSAE 16!

SERVICE ORGANIZATION CONTROL REPORTS SM. Formerly SAS 70 Reports

Update on AICPA Assurance Services Executive Committee Activities

Service Organization Control Reports

Reports on Service Organizations Where we ve been?

Frequently asked questions: SOC 2 and 3

Feeley & Driscoll, P.C. Certified Public Accountants / Business Consultants Visit us on the web: Or Call:

Service Organization Control (SOC) reports What are they?

Update on Industry Progress in Implementing Electronic Prescribing for Controlled Substances

Service Organization Control (SOC) Reports Focus on SOC 2 Reporting Standard

Farewell to SAS 70. What you need to know about the New Standard for Service Organization Reporting

Monitoring Outside Service Providers, Part III: SAS 70 Updates

Shared Service System Audits: What User Management and Auditors Need to Know

Effectively using SOC 1, SOC 2, and SOC 3 reports for increased assurance over outsourced operations. kpmg.com

SECTION I INDEPENDENT SERVICE AUDITOR S REPORT

SSAE 16 Everything You Wanted To Know But Are Afraid To Ask. Kurt Hagerman CISA, CISSP, QSA Managing Director, Coalfire December 8, 2011

Information for Management of a Service Organization

SOC Readiness Assessments. SOC Report - Type 1. SOC Report - Type 2. Building Trust and Confidence in Third-Party Relationships

FAQs New Service Organization Standards and Implementation Guidance

The Changing SAS 70 Landscape Dan Hirstein Director Rebecca Goodpasture Senior Manager Deloitte & Touche LLP January 13, 2011

ASSESSMENT REPORT Federal PKI Compliance Report September 6, 2013

California State Board of Pharmacy and Medical Board of California

About the Presenter. Presentation Objectives. SaaS / Cloud Computing Risk Management AICPA Attest Alternatives

Cloud Computing An Auditor s Perspective

WRITTEN TESTIMONY OF AICPA EMPLOYEE BENEFIT PLAN AUDIT QUALITY CENTER EXECUTIVE COMMITTEE

Audit, Review, Compilation, and Preparation of Financial Statements

Risky Business. Is Your Cybersecurity in Cruise Control? ISACA Austin Chapter Meeting May 5, 2015

Cloud Computing Risk Assessment

Vendor Management Best Practices

G13 USE OF RISK ASSESSMENT IN AUDIT PLANNING

The Finance & Audit (F&A) Committee is expected to consider F&A Committee Agenda Item 4: at its meeting on December 7, 2015.

TIS Section 9520, SSAE No. 16, Reporting on Controls at a Service Organization

Understanding ISO and Preparing for the Modern Era of Cloud Security

Understanding SOC Reports for Effective Vendor Management. Jason T. Clinton January 26, 2016

Service Organization Control (SOC) Reports

GUIDELINES INDEPENDENT CERTIFIED PUBLIC ACCOUNTANTS PERFORMING FINANCIAL STATEMENT AUDITS OF STATE AGENCIES

OFFICE OF AUDITS & ADVISORY SERVICES CLOUD COMPUTING AUDIT FINAL REPORT

AHIA HCCA Auditing & Monitoring Focus Group Defining the Key Roles and Responsibilities Corporate Compliance and Internal Audit.

Prüfung von Outsourcing mit SAS70

At a glance. A provision to require a written assertion from company management is the most notable difference between the two standards.

Webtrends Inc. Service Organization Controls (SOC) 3 SM Report on the SaaS Solutions Services System Relevant to Security

THE DATA CENTER COMPLIANCE ACRONYMS YOU NEED TO KNOW

IAASB Main Agenda (June 2010) Agenda Item. April 28, 2009

ISO 9001 Quality Management System Lead Auditor Training (IRCA)

CFPB Readiness Series: Compliant Vendor Management Overview

The 7 Deadly Sins of SAS 70 s

WELCOME TO SECURE

Role is Broader and More Strategic

A Planning Guide for Electronic Prescriptions for Controlled Substances (EPCS)

Effective Monitoring of Outsourced Plan Recordkeeping and Reporting Functions

May 21, Docket No. DEA-218. Dear Drug Enforcement Administration;

Re: Docket No. DEA-218, Electronic Prescriptions for Controlled Substances

TERMS OF REFERENCE OF THE AUDIT COMMITTEE UNDER THE BOARD OF DIRECTORS OF CHINA PETROLEUM & CHEMICAL CORPORATION

Copyright 2015, American Institute of Certified Public Accountants, Inc. All Rights Re... STATEMENT ON STANDARDS FOR CONSULTING SERVICES

Risk & Control Considerations for Outsourced IT Operations

NEW SCHEME FOR THE INFORMATION SECURITY MANAGEMENT WITH ISO 27001:2013

Independent Accountants Report

Electronic Prescribing In New York State

The silver lining: Getting value and mitigating risk in cloud computing

Assessing & Managing IT Risks: Using ISACA's CobiT & Risk IT Frameworks

The Elephant in the Room: What s the Buzz Around Cloud Computing?

Obtaining Quality Employee Benefit Plan Audit Services: The Request for Proposal and Auditor Evaluation Process

HIPAA Compliance and Reporting Requirements

Third Party Risk Management 12 April 2012

SSAE 16 & SAS 70 A Primer on Changes to Service Organization Audit Standards

E-PRESCRIBING OF CONTROLLED SUBSTANCES

G11 EFFECT OF PERVASIVE IS CONTROLS

Chapter 04. Board of Public Accountancy.

Vendor Management Compliance Top 10 Things Regulators Expect

CHARTER OF THE AUDIT COMMITTEE OF THE BOARD OF DIRECTORS

SOC on Amazon Web Services (AWS) What You Need To Know Understanding the regulatory roadmap for SOC on AWS

E-Prescribing of Controlled Substances (EPCS) New York State Board for Podiatry

The Secure WebEx Meeting Experience

HITRUST CSF Assurance Program

Navigating the transition to CSAE 3416

System Description of the Date Center System Relevant to Security and Availability (SOC 3) November 1, 2011 through April 30, 2012

G24: Audits of Controls at a Service Organization: New Standards SSAE 16 and ISAE 3402 Duff Donnelly and Jeffrey Spivack, Grant Thornton LLP

Certified Information Systems Auditor (CISA)

SSAE 16 for Transportation & Logistics Companies. Chris Kradjan Kim Koch

Communications Between Predecessor and Successor Auditors

Brown Smith Wallace, LLC

UNITED STATES OF AMERICA FEDERAL TRADE COMMISSION

AUDIT OF SBA S SYSTEM AUDIT REPORT NUMBER 4-42 SEPTEMBER 10, 2004

Independent Service Auditor s Report

Orchestrating the New Paradigm Cloud Assurance

A Leading Firm. Services Audit Tax Business Advisory

How To Pass An Assurance Course

ERIC M. WRIGHT, cpa, citp

Roles and Responsibilities Corporate Compliance and Internal Audit

eprescribing and EPCS

Questions from GAQC Conference Call The Impact of SAS 112 on Governmental Financial Statement Audits January 4, 2007

Reporting on Pro Forma Financial Information

Transcription:

EPCS Third party audits the CPA perspective 13 September 2012

Agenda Introduction History Report review Audit process Moving forward

Introduction

1311.300 Application provider requirements Third-party audits or certifications. (a) Except as provided in paragraph (e) of this section, the application provider of an electronic prescription application or a pharmacy application must have a third-party audit of the application that determines that the application meets the requirements of this part at each of the following times: (1) Before the application may be used to create, sign, transmit, or process controlled substance prescriptions. (2) Whenever a functionality related to controlled substance prescription requirements is altered or every two years, whichever occurs first. (b) The third-party audit must be conducted by one of the following: (1) A person qualified to conduct a SysTrust, WebTrust, or SAS 70 audit. (2) A Certified Information System Auditor who performs compliance audits as a regular ongoing business activity. (c) An audit for installed applications must address processing integrity and determine that the application meets the requirements of this part. (d) An audit for application service providers must address processing integrity and physical security and determine that the application meets the requirements of this part.

Personal Background Chris Halterman, Executive Director, Ernst & Young Advisory Services Chair American Institute of Certified Public Accountants (AICPA) Trust/Data Integrity Task Force 24 years performing audits in the healthcare industry Chaired AICPA efforts to address EPCS reporting

And now terminology Criteria--are the standards or benchmarks used to measure and present the subject matter and against which the practitioner evaluates the subject matter. Trust Services criteria a set of criteria used to evaluate internal control of a System as it relates to security, availability, processing integrity, confidentiality and privacy SysTrust SM and WebTrust SM Reports accounts audit reports that use the trust services criteria to evaluate systems and e-commerce systems, respectively. SAS 70 Report an audit on controls relevant to user entities internal control over financial reporting. Replace by a Service Organization Control 1 report (often referred to as a SOC 1 or SSAE 16 report) A person qualified to conduct a SysTrust, WebTrust, or SAS 70 audit a Certified Public Accountant licensed by the state board of accountancy of the state in which the report is to be issued Certified Information System Auditor (CISA) a person who has passed the CISA exam and meets the education requirements established by ISACA (formerly, the Information Systems Audit and Control Association)

Goals Understand what is required Understand how the requirements were established Understand what it means for your organization Identify developing issues

AICPA Operation Model for New Reports Understand the needs of the users Identify the criteria to be used Evaluate the criteria for suitability Draft a model report Provide guidance to CPAs

History

Events to date AICPA become aware of interim final rule Responsibility assigned to Trust/Data Integrity Task Force Working group created to understand the requirements of the Rule Interaction with industry leaders Draft report created/sent to DEA Comments received from DEA Changes made in response to DEA comments Revised report submitted to DEA Guidance published by AICPA

Analysis of requirements a third-party audit of the application that determines that the application meets the requirements of this part Identification of the requirements Evaluation of the requirements to meet the definition of suitable criteria The third-party audit must be conducted by one of the following: (1) A person qualified to conduct a SysTrust, WebTrust, or SAS 70 audit. note that the Rule does not require the report to conform to one of these 3 types. Gave the AICPA the flexibility needed to develop a report that met the DEA requirements

Analysis of requirements (continued) An audit for installed applications must address processing integrity and determine that the application meets the requirements of this part. Relationship of an installed application to a system to evaluate processing integrity Concept of processing integrity (d) An audit for application service providers must address processing integrity and physical security and determine that the application meets the requirements of this part. Implications of application as a service Consideration of processing integrity and physical security

Report review

AICPA illustrative reports high level review http://www.aicpa.org/interestareas/frc/auditatt est/reporting/downloadabledocuments/dea_re ports.pdf

Criteria All software Rule requirements Installed software and application service providers Trust Services criteria relevant to processing integrity and security Policies Communication Risk assessment Logical access Application development Controls over input, processing and output Monitoring

Audit process

Steps in the audit Defining the system Testing date/period Testing environment Processing integrity and security Engagement agreement Information requests Resolution of testing issues Reporting

Controlling costs Auditor costs Joint project management Personnel availability Recordkeeping Issue resolution Turn-around time Internal costs Time commitment of key personnel Delays Miscommunication/misinformation

Tips for working with auditors Organization of requested information Understanding Responsiveness Others?

Moving forward

Challenges When to start testing Rate of adoption Other healthcare system spending priorities Retesting issue

Special thanks to Steve Kelleher for his guidance and assistance

Questions?

Contact information Chris Halterman Ernst & Young LLP 801 Grand Avenue, Suite 3000 Des Moines, Iowa 50309 +1 515 362 7026 Chris.Halterman@ey.com